A method, system, device, medium and product for monitoring network flow status
By building a large flow screening module and a small flow storage module on the core gateway, traffic screening and status monitoring are performed for network traffic, the problem of excessive computing and memory overhead in the existing technology is solved, and efficient network flow status monitoring is achieved.
Patent Information
- Application Number
- CN202411650201.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-19
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2044-11-19
AI Technical Summary
The prior art fails to effectively filter traffic types in network traffic monitoring, resulting in excessive computing and memory overhead, and the allocation of storage units of the same size in different states leads to wasted storage space.
The large flow filtering module and small flow storage module are built on the static random access memory of the core gateway. The stream is mapped to the corresponding module through a hash function for traffic filtering and status monitoring, and differentiated state operations are performed for large flow and small flow respectively.
By real-time identification of traffic types for filtering, we can improve monitoring efficiency, reduce memory and computing resources consumption, and avoid waste of storage space.
Smart Images

Figure CN119172324B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network traffic monitoring, and in particular to a method, system, device, medium and product for monitoring network flow status. Background Art
[0002] In network traffic measurement, continuously monitoring the status of each flow is crucial for fine-grained network management and detecting malicious traffic or abnormal behavior. This is an important means to ensure network security. According to specific monitoring requirements, a group of data packets with the same flow label is usually abstracted as a flow, and the network flow label and flow status can be flexibly defined according to the application scenario. For example, all data packets sent to the same destination address can be regarded as a flow, and the destination address is the label of this flow. At the same time, the status of the flow can be defined as the TCP session status or the priority of the flow. In a TCP session, control flags (such as ACK, RST, SYN, and FIN) can be used to indicate the connection status of the flow. When the RST or FIN flag bit is set, it usually means that the TCP connection is reset or terminated. Changes in such flag bits may be related to RST or FIN attacks, and an alarm should be generated at this time. Tracking the status of each flow is crucial for locating suspicious TCP flows. For example, if a large amount of traffic remains in the SYN-RECEIVED state for a long time, it may indicate a TCP SYN flood attack, affecting the normal service response of legitimate traffic. Therefore, monitoring the flow status and its distribution is a basic operation for detecting network anomalies.
[0003] However, performing such monitoring tasks in a high-speed network is extremely challenging, mainly reflected in the computational and memory overhead. The Bloom filter is an efficient probabilistic data structure commonly used for set membership queries. The method based on the Bloom filter is widely used in many network applications due to its low false positive rate and low insertion and query complexity, thus effectively reducing the memory and bandwidth costs of information processing. Existing research attempts to replace the bit cells in the Bloom filter with status cells to store flow status information, and this method can support approximate flow status queries. However, these technologies have two major challenges: First, the skewness of the flow size distribution: In a real network environment, about 95% of the flows are small flows that contain only a small number of data packets, while a small number of large flows occupy the vast majority of the total traffic. The rapid influx of large flows will cause a large number of status operations, significantly reducing the processing efficiency. Second, the skewness of the flow status distribution: In a TCP connection, about 95% of the data packets set the ACK flag bit to maintain a reliable connection. Allocating the same size of storage units for different statuses will lead to low utilization of storage resources. The counters required for frequent statuses (such as ACK) are large, while infrequent statuses waste storage space, resulting in too high memory overhead. Summary of the Invention
[0004] To this end, the technical problem to be solved by the present invention is to overcome the problem that the monitoring of network flow status in the prior art does not screen traffic types, and also to overcome the problem of waste of storage space caused by allocating the same size of storage units to flows in different states.
[0005] To solve the above technical problems, the present invention provides a method for monitoring network flow status, including:
[0006] Step S1: In each measurement period, construct two memory spaces on the static random access memory of the core gateway as a large flow screening module and a small flow storage module;
[0007] Step S2: Map the flow to be monitored into the large flow screening module for traffic screening. If it is determined that the flow is a large flow, perform corresponding flow status operations in the large flow screening module to achieve traffic status monitoring; if it is determined that the flow is a small flow, map the flow to the small flow storage module and perform corresponding flow status operations to achieve traffic status monitoring;
[0008] Among them, the flow status operations include insert operation, delete operation, update operation and query operation. The large flow is a flow with the number of data packets exceeding a preset number, and the small flow is a flow with the number of data packets not exceeding a preset number.
[0009] In an embodiment of the present invention, the method of the insert operation is:
[0010] When each data packet in the flow arrives in the form of a flow-status pair perform an insert operation on the flow-status pair : First, use a hash function to map the flow-status pair to the th bucket of the large flow screening module, and the mapping formula is: ;
[0011] ;
[0012] Among them, represents the th bucket, and the bucket is a register, is the hash function, is the modulo calculation, is the number of buckets. Among them, each bucket includes four fields, namely , , , , is used to store the flow label, is used to store the flow status, Used to count the number of data packets with the same flow label as this bucket, used to count the number of data packets with different flow labels from this bucket;
[0013] According to the filling content situation of the bucket, different insertion operations are taken.
[0014] In an embodiment of the present invention, the method of taking different insertion operations according to the filling content situation of the bucket includes:
[0015] If the bucket is empty, that is, , then directly insert the flow - status pair into this bucket: Modify and to and respectively, set to 1 to count this data packet, where represents the empty type;
[0016] If the flow recorded in the bucket is the same as the flow to which the flow - status pair belongs, that is, , then increase the value of by 1 to count this data packet;
[0017] If the flow recorded in the bucket is different from the flow to which the flow - status pair belongs, that is, , and , then increase the value of by 1 to count the number of data packets mapped to this bucket and having different flow labels; At the same time, send the flow - status pair to the small - flow storage module for recording. The small - flow storage module includes flow - status storage units. By using hash functions, map the flow - status pair to flow - status storage units, and modify its storage status to . The formula is:
[0018] ;
[0019] Wherein, is the th of the small - flow storage module A flow status storage unit, is the th hash function among hash functions;
[0020] If the flow recorded in the th bucket is different from the flow-flow status pair it belongs to, that is , and , first send the flow-status pair stored in the th bucket to the small flow storage module for recording. By using hash functions, map the flow-status pair to flow status storage units, and modify its storage status to , the formula is:
[0021] ;
[0022] Then reset the th bucket and insert the flow-status pair into this bucket: Modify and to and respectively, set to 1 to count this data packet, and reset to 0.
[0023] In an embodiment of the present invention, the method of the deletion operation is:
[0024] For the stored flow, perform a deletion operation: First, use the hash function to map the stored flow to the th bucket of the large flow screening module , the label of this stored flow is . If the flow with the label is the same as the flow stored in this bucket, that is , then clear or reset all fields of this bucket to delete this flow status record; if the flow with the label is different from the flow stored in this bucket, that is , then send the flow with the label to the small flow storage module for deletion. By mapping this stored flow to flow status storage units , and clear its storage status.
[0025] In one embodiment of the present invention, the method of the query operation is as follows:
[0026] Perform a query operation on a given flow: First, use a hash function to map the stored flow to the th bucket of the large flow screening module. The label of the stored flow is . If the flow with the label is the same as the flow stored in this bucket, that is, , then return the flow status stored in this bucket as the query result; if the flow with the label is different from the flow stored in this bucket, that is, , then send the flow with the label to the small flow storage module for query. By mapping it to flow status storage units, and taking the intersection of the status values of flow status storage units as the query result and returning it. The formula is:
[0027] ;
[0028] wherein, is the intersection symbol.
[0029] In one embodiment of the present invention, the method of the update operation is as follows:
[0030] Perform an update operation on a given flow: First perform a delete operation, and then perform an insert operation.
[0031] To solve the above technical problems, the present invention provides a network flow status monitoring system, including:
[0032] A construction module: used to construct two memory spaces on the static random access memory of the core gateway as the large flow screening module and the small flow storage module in each measurement period;
[0033] A traffic status monitoring module: used to map the flow to be monitored into the large flow screening module for traffic screening. If it is determined that this flow is a large flow, perform corresponding flow status operations in the large flow screening module to achieve traffic status monitoring; if it is determined that this flow is a small flow, map this flow to the small flow storage module and perform corresponding flow status operations to achieve traffic status monitoring;
[0034] wherein, the flow status operations include insert operation, delete operation, update operation and query operation. The large flow is a flow with the number of data packets exceeding a preset number, and the small flow is a flow with the number of data packets not exceeding a preset number.
[0035] To solve the above technical problems, the present invention provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the steps of the network flow status monitoring method as described above are implemented.
[0036] To solve the above technical problems, the present invention provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the network flow status monitoring method as described above are implemented.
[0037] To solve the above technical problems, the present invention provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of the network flow status monitoring method as described above are implemented.
[0038] The above technical solution of the present invention has the following advantages compared with the prior art:
[0039] The network flow status monitoring method of the present invention screens by real-time identifying the traffic type, and performs differential status monitoring for different traffic types (specifically, the status monitoring of traffic can be realized through insert operations, delete operations, update operations, and query operations), so as to improve the monitoring efficiency and reduce the consumption of memory and computing resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to make the content of the present invention easier to be clearly understood, the following further describes the present invention in detail according to the specific embodiments of the present invention in conjunction with the accompanying drawings.
[0041] Figure 1 is the flowchart of the method of the present invention;
[0042] Figure 2 is the block diagram of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0043] The following further describes the present invention in conjunction with the accompanying drawings and specific embodiments, so that those skilled in the art can better understand the present invention and be able to implement it, but the embodiments cited do not limit the present invention. Embodiment 1
[0044] Referring to Figure 1 and Figure 2 shown, the present invention relates to a network flow status monitoring method, including:
[0045] Step S1: In each measurement period, construct two memory spaces on the static random access memory of the core gateway as a large flow screening module and a small flow storage module;
[0046] Step S2: Map the flow to be monitored into the large flow screening module for traffic screening. If it is determined that the flow is a large flow, perform corresponding flow status operations in the large flow screening module to achieve traffic status monitoring; if it is determined that the flow is a small flow, map the flow to the small flow storage module and perform corresponding flow status operations to achieve traffic status monitoring;
[0047] Among them, the flow status operations include insertion operation, deletion operation, update operation and query operation. The large flow is a flow with the number of data packets exceeding a preset number, and the small flow is a flow with the number of data packets not exceeding a preset number.
[0048] The following is a detailed introduction to this embodiment:
[0049] The network flow status monitoring method proposed in this embodiment mainly includes four flow status operations: insertion, deletion, update and query. All operations are performed on the static random access memory (SRAM) of the core gateway of the network link. In each measurement period, two memory spaces will be opened on the SRAM for the large flow screening module and the small flow storage module respectively. When it is necessary to monitor a flow, first use a hash function to map the flow to a register (i.e., bucket) in the large flow screening module according to the flow label for traffic screening. If it is determined that the flow is a large flow, perform corresponding flow status operations in the register. Otherwise, if it is determined that the flow is a small flow, use a hash function to map the flow to multiple flow status storage units in the small flow storage module according to the flow label and perform corresponding flow status operations. After a measurement period ends, the SRAM will reset the opened memory space. The specific implementation method is as follows:
[0050] At the beginning of each measurement period, the core gateway will open a memory space on the SRAM for the large flow screening module , and this large flow screening module contains a hash function and registers ( ), and each register contains four fields: used to store the flow label, used to store the flow status, used to count the number of data packets with the same flow label as this register, used to count the number of data packets with different flow labels from this register. In addition, the core gateway will also open a memory space on the SRAM for the small flow storage module , and this module contains flow status storage units, and use hash functions ( ) to map the flow to A corresponding flow status storage unit. For each incoming flow-status pair , corresponding processing is performed according to different operations required.
[0051] 1. Insertion operation. When a new flow arrives (when each data packet in the flow arrives in the form of a flow-status pair ), an insertion operation is performed on the flow-status pair . First, it is mapped to the th bucket of the large flow screening module by means of a hash function. The specific mapping formula is:
[0052] (1);
[0053] where, represents the th bucket, is any hash function with good randomness, is the modulo operation, is the number of buckets.
[0054] Then, different insertion operations are taken according to the content filling situation of the bucket. The specific methods are as follows:
[0055] (1) If the bucket is empty, that is, , then directly insert the flow-status pair into this bucket: modify and to and respectively, and set to 1 to count this data packet. Among them, represents the empty type;
[0056] (2) If the flow recorded in the bucket is the same as the flow to which the flow-status pair belongs, that is, , then increase the value of by 1 to count this data packet;
[0057] (3) If the flow recorded in the bucket is different from the flow to which the flow-status pair belongs, that is, , and , then increase the value of by 1 to count the number of data packets mapped to this bucket and having different flow labels. At the same time, send the flow-status pair to the small flow storage module for recording. Specifically, this embodiment uses hash functions to select a flow status storage unit and modify its storage status to , the specific method is as follows:
[0058] (2);
[0059] Among them, is the th flow status storage unit of the small flow storage module is a series of independent and well-randomized hash functions, corresponding to the th hash function among the hash functions;
[0060] (4) If the flow recorded in this bucket is different from the flow to which the flow-status pair belongs ( ), and , first send the flow-status pair stored in this bucket to the small flow storage module for recording. Specifically, in this embodiment, hash functions are used to map the flow-status pair to flow status storage units and modify its storage status to , the specific method is as follows:
[0061] (3);
[0062] Then, reset this bucket and insert the flow-status pair into this bucket: modify and to and respectively, set to 1 to count the data packet, and reset to 0.
[0063] (II) Deletion operation (for the stored flow). For the flow status deletion operation of the flow with the label , first map it to the th bucket of the large flow screening module by means of a hash function. If the flow with the label is the same as the flow stored in this bucket, that is, , then clear or reset all fields of this bucket to delete this flow status record. Otherwise, if the flow with the label , the flow labeled is sent to the small flow storage module for deletion. Specifically, in this embodiment, it is mapped to flow status storage units , and its storage status is cleared.
[0064] (3) Query operation (for a given flow). For the flow labeled , a flow status query operation is performed. First, it is mapped to the th bucket of the large flow screening module by means of a hash function. If the flow labeled is the same as the flow stored in this bucket, that is, , then the flow status stored in this bucket is returned as the query result. Otherwise, if the flow labeled is different from the flow stored in this bucket, that is, , then the flow labeled is sent to the small flow storage module for query. Specifically, in this embodiment, by mapping it to flow status storage units, and taking the intersection of the status values of flow status storage units as the query result and returning it. The specific operation is as follows:
[0065] (4);
[0066] (4) Update operation (for a given flow). The flow status update operation of the flow labeled mainly consists of the deletion operation of the old flow-status pair and the insertion operation of the new flow-status pair. The specific operation is the same as the above content and will not be elaborated here.
[0067] In this embodiment, the traffic status is monitored through the following four operations:
[0068] Insertion operation, used to store new traffic status information;
[0069] Deletion operation, used to delete the stored traffic status information;
[0070] Query operation, used to query the traffic status information of a given flow;
[0071] Update operation, used to update the traffic status information of a given flow.
[0072] (1) The specific implementation of the insertion operation includes the following steps:
[0073] S2.1: Calculate the serial number of the bucket mapped to the large flow screening module according to formula (1). ;
[0074] S2.2: Check the storage status of the th bucket (i.e., );
[0075] S2.3: If it is empty, directly insert the flow - status pair into this bucket: Modify and to respectively, and set and , and set to 1 to count this data packet;
[0076] S2.4: If the flow recorded in this bucket is the same as the flow to which the flow - status pair belongs, that is, , then increase the value of by 1 to count this data packet;
[0077] S2.5: If the flow recorded in this bucket is different from the flow to which the flow - status pair belongs ( ), and , then increase the value of by 1;
[0078] S2.6: Calculate the serial numbers of the flow - status storage units mapped to the small flow storage module according to formula (2);
[0079] S2.7: Insert the flow status into the flow - status storage units mapped according to formula (2);
[0080] S2.8: If the flow recorded in this bucket is different from the flow to which the flow - status pair belongs ( ), and , then calculate the serial numbers of the flow mapped to the flow - status storage units in the small flow storage module according to formula (3) for the flow with the label in the original bucket;
[0081] S2.9: Insert the flow status stored in the original bucket into the flow - status storage units mapped according to formula (3);
[0082] S2.10: Reset this bucket and the flow - status pair Insert this bucket: and are respectively modified to and , set to 1 to count this data packet, and set to 0.
[0083] (2) The specific implementation of the deletion operation includes the following steps:
[0084] S3.1: Calculate the serial number of the bucket mapped to the large flow screening module according to formula (1) ;
[0085] S3.2: Check the storage status of the bucket (i.e., );
[0086] S3.3: If the flow with the label is the same as the flow stored in , that is, , then empty or reset all fields of ;
[0087] S3.4: If the flow with the label is different from the flow stored in this bucket, that is, , then calculate the serial number of the flow mapped to the flow status storage units in the small flow storage module according to formula (2);
[0088] S3.5: Reset the flow status storage units mapped to.
[0089] (3) The specific implementation of the query operation includes the following steps:
[0090] S4.1: Calculate the serial number of the bucket mapped to the large flow screening module according to formula (1) ;
[0091] S4.2: Check the storage status of the bucket ;
[0092] S4.3: If the flow with the label is the same as the flow stored in , that is, , then return as the query result;
[0093] S4.4: If the flow with the label is different from the flow stored in this bucket, that is, , then calculate according to formula (2) the sequence number of the flow state storage units in the small flow storage module to which the flow with the label is mapped; flows are mapped; S4.5: Calculate according to formula (4) the stored information of the mapped flow state storage units and return the calculated value as the query result.
[0094] S4.5: Calculate according to formula (4) the stored information of the mapped flow state storage units and return the calculated value as the query result. mapped flow state storage units and return the calculated value as the query result.
[0095] (4) The specific implementation of the update operation includes the following steps:
[0096] For the flow state update operation of the flow with the label : First perform a delete operation, and then perform an insert operation. Example 2 Example 2
[0097] This embodiment provides a network flow state monitoring system, including:
[0098] A construction module: used to construct two memory spaces on the static random access memory of the core gateway as a large flow screening module and a small flow storage module in each measurement period;
[0099] A traffic state monitoring module: used to map the flow to be monitored into the large flow screening module for traffic screening. If it is determined that the flow is a large flow, perform corresponding flow state operations in the large flow screening module to implement traffic state monitoring; if it is determined that the flow is a small flow, map the flow into the small flow storage module and perform corresponding flow state operations to implement traffic state monitoring;
[0100] Among them, the flow state operations include insert operation, delete operation, update operation and query operation. The large flow is a flow with the number of data packets exceeding a preset number, and the small flow is a flow with the number of data packets not exceeding a preset number. Example 3
[0101] This embodiment provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the steps of the network flow state monitoring method described in Example 1 are implemented. Example 4
[0102] This embodiment provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the network flow state monitoring method described in Example 1 are implemented. Example 5
[0103] This embodiment provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of the network flow state monitoring method described in Example 1 are implemented.
[0104] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code. The solutions in the embodiments of the present application can be implemented in various computer languages. For example, object-oriented programming languages such as Java and interpreted scripting languages such as JavaScript.
[0105] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0106] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0107] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0108] Although the preferred embodiments of the present application have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn the basic creative concept. Therefore, the appended claims are intended to be construed as including the preferred embodiments as well as all changes and modifications that fall within the scope of the present application.
[0109] Obviously, the above embodiments are merely examples given for clear illustration and are not limitations on the implementation manners. For those of ordinary skill in the art, other different forms of changes or alterations can be made based on the above description. It is not necessary and impossible to enumerate all implementation manners here. And the obvious changes or alterations derived therefrom still fall within the protection scope of the present invention.
Claims
1. A network flow status monitoring method, characterized in that: include: Step S1: In each measurement cycle, two memory spaces are constructed on the static random access memory of the core gateway as a large flow screening module and a small flow storage module; Step S2: Map the flow to be monitored to the large flow screening module for flow screening. If the flow is judged to be a large flow, a corresponding flow state operation is performed in the large flow screening module to realize flow state monitoring; if the flow is judged to be a small flow, the flow is mapped to the small flow storage module and a corresponding flow state operation is performed to realize flow state monitoring; The flow state operation includes an insert operation, a delete operation, an update operation and a query operation, the large flow is a flow whose number of data packets exceeds a preset number, and the small flow is a flow whose number of data packets does not exceed a preset number; The method of the insertion operation is: Each packet in a flow is passed through a flow-state pair When it arrives in the form of To insert the data, first use the hash function to convert the stream-state pair Mapping to the high-volume filtering module No. The mapping formula for each bucket is: ; in, Indicates bucket, the bucket is a register, is a hash function, For modulo calculation, is the number of buckets, where each bucket includes four fields, namely , , , , Used to store flow labels. Used to store stream status, Used to count the number of packets with the same flow label as the bucket. Used to count the number of data packets with different flow labels from the bucket; Small flow storage module include flow state storage unit, by using A hash function converts the flow-state pair Map to A stream state storage unit is created, and its storage state is modified to .
2. The network flow status monitoring method according to claim 1, characterized in that: The method of inserting operation also includes: According to Different insertion operations are performed based on the filling content of each bucket.
3. The network flow status monitoring method according to claim 2, characterized in that: According to the The following methods are used to insert different contents of a bucket: Jordi bucket is empty, that is , then directly convert the flow-state pair Insert into the bucket: and Modified to and ,Will Set to 1 to count the packet, where Represents an empty type; Jordi Streams and stream-state pairs recorded in buckets The same stream, that is , then The value of is increased by 1 to count the packet; Jordi Streams and stream-state pairs recorded in buckets The streams are different, that is ,and , then The value of is increased by 1 to count the number of packets mapped to the bucket and with different flow labels; at the same time, the flow-state pair Send to small stream storage module To record, the formula is: ; in, Storage module for small streams No. flow state storage unit, for The hash function A hash function, It is an assignment operation; Jordi Streams and stream-state pairs recorded in buckets The streams are different, that is ,and , first Stream-state pairs stored in buckets Send to small stream storage module To record, use A hash function converts the flow-state pair Map to A stream state storage unit is created, and its storage state is modified to , the formula is: ; Reset bucket and convert the stream-state pair Insert into the bucket: and Modified to and ,Will Set to 1 to count the packet and Reset to 0.
4. The network flow status monitoring method according to claim 3 is characterized in that: The method of the deletion operation is: Deleting the stored streams: First, use the hash function to map the stored streams to the large stream filtering module. No. The stored flow label is , if the label is The stream of is the same as the stream stored in the bucket, that is, , then clear or reset all domains of the bucket to delete the stream status record; if the tag is The stream of is different from the stream stored in the bucket, that is, , then label it as The stream is sent to the small stream storage module To delete, map the stored stream to Stream state storage unit , and clear its storage state.
5. The network flow status monitoring method according to claim 3 is characterized in that: The method of the query operation is: To query a given stream: First, use the hash function to map the stored stream to the large stream filtering module. No. The stored flow label is , if the label is The stream of is the same as the stream stored in the bucket, that is, , then the stream state stored in the bucket Return as query result; if the tag is The stream of is different from the stream stored in the bucket, that is, , then label it as The stream is sent to the small stream storage module To query, by mapping it to flow state storage unit, and The state values of the flow state storage units are intersected and returned as the query result. The formula is: ; in, To take the intersection symbol.
6. The network flow status monitoring method according to claim 1, characterized in that: The update operation method is: Perform an update operation on a given stream: first perform a delete operation, then perform an insert operation.
7. A network flow status monitoring system, characterized in that: include: Building module: used to build two memory spaces on the static random access memory of the core gateway as a large flow screening module and a small flow storage module in each measurement cycle; Traffic status monitoring module: used to map the flow to be monitored to the large flow screening module for flow screening. If the flow is judged to be a large flow, the corresponding flow status operation is performed in the large flow screening module to realize traffic status monitoring; if the flow is judged to be a small flow, the flow is mapped to the small flow storage module and the corresponding flow status operation is performed to realize traffic status monitoring; The flow state operation includes an insert operation, a delete operation, an update operation and a query operation, the large flow is a flow whose number of data packets exceeds a preset number, and the small flow is a flow whose number of data packets does not exceed a preset number; The method of the insertion operation is: Each packet in a flow is passed through a flow-state pair When it arrives in the form of To insert the data, first use the hash function to convert the stream-state pair Mapping to the high-volume filtering module No. Bucket, the mapping formula is: ; in, Indicates bucket, the bucket is a register, is a hash function, For modulo calculation, is the number of buckets, where each bucket includes four fields, namely , , , , Used to store flow labels. Used to store stream status, Used to count the number of packets with the same flow label as the bucket. Used to count the number of data packets with different flow labels from the bucket; Small flow storage module include flow state storage unit, by using A hash function converts the flow-state pair Map to A stream state storage unit is created, and its storage state is modified to .
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the network flow status monitoring method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the network flow status monitoring method according to any one of claims 1 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the network flow status monitoring method described in any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Accurate active large flow identification method and system based on small flow filtering
CN115102907A